You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 8 macOS应用App Store审核时出现开发者验证错误

.NET 8 macOS应用App Store审核遇Gatekeeper验证失败问题

问题现象

  • App Store审核反馈:应用启动出错,提示「无法打开应用,因为无法验证开发者,这可能与应用的Gatekeeper合规性问题有关」
  • 审核截图显示:「应用已损坏,无法打开,请从App Store删除并重新安装」
  • TestFlight安装后无此问题

打包流程

  1. 构建应用:dotnet build {SolutionFileName} --configuration Release
  2. 签名应用:codesign --force --verify --verbose --deep --options runtime --timestamp --entitlements ../Entitlements.plist -s '3rd Party Mac Developer Application: [ID]' Demo.app
  3. 创建安装包:productbuild --component Demo.app /Applications --sign '3rd Party Mac Developer Installer: [ID]' Demo.pkg

Entitlements.plist配置

<key>com.apple.application-identifier</key>
<string>[ID].com.demo.appc</string>
<key>com.apple.developer.team-identifier</key>
<string>[ID]</string>   
<key>com.apple.security.app-sandbox</key>
<true/>
<key>com.apple.security.files.user-selected.read-write</key>
<true/>
<key>com.apple.security.network.client</key>
<true/>
<key>com.apple.security.files.bookmarks.app-scope</key>
<true/>
<key>com.apple.security.cs.allow-jit</key>
<true/>
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
<true/>
<key>com.apple.security.cs.allow-dyld-environment-variables</key>
<true/>
<key>com.apple.security.cs.disable-library-validation</key>
<true/>

项目发布配置片段

<PropertyGroup Condition=" '$(Configuration)|$(Platform)' == 'Release|AnyCPU' ">  
    <OutputPath>bin\Release</OutputPath>   
    <Optimize>true</Optimize>
    <NoStdLib>true</NoStdLib>
    <UseSGen>false</UseSGen>
    <UseRefCounting>false</UseRefCounting>
    <TlsProvider>Default</TlsProvider>        
    <PublishTrimmed>true</PublishTrimmed>    
    <TrimMode>partial</TrimMode>
    <RunAOTCompilation>false</RunAOTCompilation>    
    <EnablePackageSigning>true</EnablePackageSigning>
    <CodeSigningKey>3rd Party Mac Developer Application:[ID]</CodeSigningKey>
    <EnableCodeSigning>True</EnableCodeSigning>
    <CreatePackage>false</CreatePackage>    
    <PackageSigningKey>3rd Party Mac Developer Installer:[ID]</PackageSigningKey>
    <Profiling>false</Profiling>
    <CodeSignProvision>provfile</CodeSignProvision>
    <CodeSignEntitlements>Entitlements.plist</CodeSignEntitlements>    
    <LangVersion>default</LangVersion>
</PropertyGroup>

证书状态

执行security find-identity -vp macappstore输出:

5) "3rd Party Mac Developer Application: [ID]" (Missing required extension)
6) "3rd Party Mac Developer Installer: [ID]" (Missing required extension)

问题分析与解决方案

1. 修复证书缺失扩展问题

证书提示「Missing required extension」是核心原因,直接导致Gatekeeper无法验证签名:

  • 登录Apple开发者后台,删除现有Mac开发/安装证书,重新生成对应Mac App Store分发的证书(确保证书类型选择正确,不要选成开发用证书)
  • 下载新证书导入Keychain后,重新执行security find-identity -vp macappstore,确认不再显示「Missing required extension」

2. 优化签名流程

  • 关闭项目文件中的<EnableCodeSigning>True</EnableCodeSigning>和<EnablePackageSigning>true</EnablePackageSigning>,避免dotnet自动签名与手动签名冲突
  • 签名时移除--deep参数,.NET应用无需深度签名,改为仅签名主App包:
    codesign --force --verify --verbose --options runtime --timestamp --entitlements ../Entitlements.plist -s '3rd Party Mac Developer Application: [ID]' Demo.app
    
  • 用codesign --verify --verbose=4 Demo.app检查签名完整性,确保所有嵌套组件签名有效

3. 调整构建命令

替换dotnet build为dotnet publish,确保打包所有依赖项:

dotnet publish {ProjectFileName} --configuration Release --runtime osx-x64 --self-contained false

(根据你的硬件架构调整runtime参数,如osx-arm64)

4. 验证权限配置

  • 确认com.apple.application-identifier格式为TeamID.BundleID,与开发者后台的App ID完全一致
  • 确保com.apple.developer.team-identifier值与证书中的TeamID一致,无拼写错误

5. 本地验证安装包

重新打包后,先本地验证合规性:

  • 用altool验证安装包:
    xcrun altool --validate-app -f Demo.pkg -t osx -u "你的Apple ID" -p "应用专用密码"
    
  • 安装后检查Gatekeeper状态:
    spctl --assess --verbose Demo.app
    
    需输出accepted才符合要求

内容的提问来源于stack exchange,提问作者jaroslavic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 18:35:02